Posted on: 08/04/2026
Description
:
Key Responsibilities
:
- Security Governance Lead the information security program, maintain policies, drive governance cadence, manage the security roadmap, and report metrics to leadership.
- Risk Management Maintain risk register, conduct assessments, review changes/vendors for security impact, and drive mitigation and risk prioritization.
- Compliance & Audits Support ISMS/SOC 2 readiness, manage audit evidence, ensure control effectiveness, and handle customer security questionnaires.
- Identity & Access Management (IAM) Govern access controls, enforce RBAC, manage onboarding/offboarding, conduct access reviews, and ensure MFA/SSO/security standards.
- Secure SDLC Embed security in development, ensure code and vulnerability controls, participate in design reviews, and drive remediation.
- Cloud & Infrastructure Security Oversee and coordinate cloud security posture, vulnerability management, DR/backup, monitoring, and system hardening with the Dev Ops Lead.
- Incident Response Oversee and manage incident response plans, coordinate triage and communication, ensure logging/alerting, and run drills.
- Vendor Security Assess and monitor third-party risks, maintain vendor inventory, and support security-related contract reviews.
- Data Protection Define data classification, ensure secure data handling, enforce encryption and access controls, and promote data minimization.
- Security Awareness Drive training programs and foster a strong security culture.
- Customer Trust Act as security POC for clients, support sales in security diligence, and represent security posture in client discussions.
Qualifications Required
:
- Bachelors degree in a relevant technical field or equivalent practical experience.
- 5+ years of progressive experience in information security, risk management, or security operations.
- 2+ years in a security management, lead, or program ownership role.
- Experience with security governance, risk assessments, vendor risk, and incident response.
- Experience supporting SOC 2 or similar control frameworks.
- Excellent communication skills with both technical teams and executive leadership.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1626913